2026 CVE Vulnerabilities
45,891 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2522 | CRITICAL | 9.8 | 0.5% | Feb 16, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/... |
| CVE-2026-2521 | CRITICAL | 9.8 | 0.7% | Feb 15, 2026 | A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re... |
| CVE-2026-26369 | CRITICAL | 9.8 | 0.6% | Feb 15, 2026 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization c... |
| CVE-2026-26366 | CRITICAL | 9.8 | 0.7% | Feb 15, 2026 | eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after ... |
| CVE-2026-1490 | CRITICAL | 9.8 | 1.2% | Feb 15, 2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi... |
| CVE-2026-1306 | CRITICAL | 9.8 | 4.5% | Feb 14, 2026 | The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension ... |
| CVE-2026-24853 | CRITICAL | 9.8 | 0.3% | Feb 13, 2026 | Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the... |
| CVE-2026-26273 | CRITICAL | 9.8 | 0.7% | Feb 13, 2026 | Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.... |
| CVE-2026-26335 | CRITICAL | 9.8 | 2.8% | Feb 13, 2026 | Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web app... |
| CVE-2026-26333 | CRITICAL | 9.8 | 0.9% | Feb 13, 2026 | Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se... |
| CVE-2026-26190 | CRITICAL | 9.8 | 27.7% | Feb 13, 2026 | Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose... |
| CVE-2026-26268 | CRITICAL | 9.9 | 0.5% | Feb 13, 2026 | Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in ver... |
| CVE-2026-26221 | CRITICAL | 9.8 | 1.1% | Feb 13, 2026 | Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf... |
| CVE-2026-23112 | CRITICAL | 9.8 | 0.4% | Feb 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu... |
| CVE-2026-26068 | CRITICAL | 9.9 | 3.3% | Feb 12, 2026 | emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadat... |
| CVE-2026-1358 | CRITICAL | 9.8 | 1.2% | Feb 12, 2026 | Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim... |
| CVE-2026-26011 | CRITICAL | 9.8 | 0.5% | Feb 12, 2026 | navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulne... |
| CVE-2026-25996 | CRITICAL | 9.8 | 0.6% | Feb 12, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-24895 | CRITICAL | 9.8 | 0.6% | Feb 12, 2026 | FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly han... |
| CVE-2026-24044 | CRITICAL | 9.2 | 0.3% | Feb 12, 2026 | Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kuberne... |
| CVE-2026-26219 | CRITICAL | 9.3 | 0.2% | Feb 12, 2026 | newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not inco... |
| CVE-2026-26218 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisi... |
| CVE-2026-26216 | CRITICAL | 10 | 1.6% | Feb 12, 2026 | Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl ... |
| CVE-2026-26214 | CRITICAL | 9.1 | 0.2% | Feb 12, 2026 | Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HT... |
| CVE-2026-1729 | CRITICAL | 9.8 | 0.6% | Feb 12, 2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now